Reference Guide

Table Of Contents
872 | show firewall Dell PowerConnect W-Series ArubaOS 6.1 CLI | Reference Guide
Only allow local
subnets in user table
If enabled, the controller only adds IP addresses which belong to a local subnet to the user
table.
Monitor/police CP
attacks
If enabled, the controller monitors a misbehaving user’s inbound traffic rate. If this rate is
exceeded, the controller can register a denial of service attack.
Rate limit CP untrusted
ucast traffic
Shows the inbound traffic rate
Rate limit CP untrusted
mcast traffic
Displays the untrusted multicast traffic rate limit.
Rate limit CP trusted
ucast traffic
Displays the trusted unicast traffic rate limit.
Rate limit CP trusted
mcast traffic
Displays the trusted multicast traffic rate limit.
Rate limit CP route
traffic
Displays the traffic rate limit for traffic that needs generated ARP requests.
Rate limit CP session
mirror traffic
Displays the traffic rate limit for session mirrored traffic forwarded to the controller.
Rate limit CP auth
process traffic
Displays the traffic rate limit for traffic forwarded to the authentication process.
Deny inter user traffic If enabled, this setting disables traffic between all untrused users. You can configure user
role policies that prevent Layer-3 traffic between users or networks but this does not block
Layer-2 traffic.
Prohibit ARP Spoofing When this option is enabled, possible arp spoofing attacks are logged and an SNMP trap is
sent.
Stateful VOCERA
Processing
VOCERA processing is disabled by default.
Stateful UA Processing UA processing is disabled by default.
Enforce bw contracts
for broadcast traffic
If enabled, bw contracts are applied ot local subnet broadcast traffic.
Multicast automatic
shaping
If enabled, enables multicast optimization and provides excellent streaming quality
regardless of the amount of VLANs or IP IGMP groups that are used.
Clear Sessions on Role
Update
If enabled, this setting clears all existing user role sessions after a user or client roles is
modified.
Enforce TCP Sequence
numbers
If enabled, prevents data from passing between two clients until the three-way TCP
handshake has been performed.
AMSDU Aggregated Medium Access Control Service Data Units (AMSDU) packets are dropped if
this option is enabled.
Session mirror IPsec If enabled, rrames are sent to IP address specified by the
session-mirror-destination
option.
Parameter Description